如要限制對 VPC Service Controls 支援的 Google Cloud服務存取權,請建立具有 CBA 存取層級的 VPC Service Controls 範圍,然後將服務新增至範圍。如需詳細操作說明,請參閱「使用 VPC Service Controls 啟用以憑證為基礎的存取權」。
將 CBA 存取權層級繫結至您要限制存取權的使用者群組,藉此限制所有 Google Cloud 服務 (包括Google Cloud 控制台) 的存取權。如需詳細操作說明,請參閱「使用使用者群組啟用以憑證為基礎的存取權」。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-07-10 (世界標準時間)。"],[[["Certificate-based access (CBA) requires the creation of a new CBA access level, its enforcement, and enabling CBA in client applications."],["Prior to setting up CBA, the Endpoint Verification Chrome extension and helper app must be deployed on all devices needing access to Google Cloud resources."],["CBA access levels can be enforced either by creating a VPC Service Controls perimeter for specific Google Cloud services or by binding the CBA access level to user groups for broader restriction."],["Once CBA is enforced, access to resources without client certificates will be denied, requiring client applications to send certificates via an mTLS connection for trusted device access."],["To complete the setup, users must ensure they enable CBA in their compatible client using the correct procedures for enabling certificate-based access in client applications."]]],[]]